Having problems removing Altnet spyware

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by cindysnoopy, Dec 6, 2004.

  1. cindysnoopy

    cindysnoopy Shotgun!

    We're having trouble removing HKEY_LOCAL_MACHINE:software\altnet\. We've updated and run Adaware, and even tried to remove it manually, but it won't allow us to delete it. Our computer has been running really sluggishly lately and we think this might be the culprit. Any advice?

    We run XP Pro.
     
  2. PhilliePhan

    PhilliePhan Guest

    Hi Cindy,

    Here is the cut & paste Standard Boilerplate ;)

    Generally, it is a good idea to start with the Cleanup Tutorial HERE:
    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan and Virus Removal

    This will remove a lot of stuff that would otherwise clog a HJT log.

    Please let us know the steps that you are able to complete and the ones that give you problems. Note that you need to be in Safe Mode with System Restore OFF (if you have it - you didn't give OS) and have the Viewing of Hidden Files ENABLED as per the instructions in the link. Make sure to do the Online Scans.

    Post back and let us know how you fared. Also, send us a HijackThis Log. Be sure to follow the instructions below:

    Note that your HijackThis should be up-to-date (v1.98.2) and MUST be extracted to its own safe folder – C:\Program Files\HijackThis!

    If you need a Fresh Download of HJT, get it HERE: HijackThis 1.98.2

    Also note that, before you scan, you MUST close all running programs including your web browser, e-mail and items in the system tray.

    Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    I am tied up these days, but somebody will take a look when they get a chance.

    Best luck :)
    PP
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  4. eclayton

    eclayton Sgt. Shorts-cough

    Thanks guys, we'll get back to you.

    Eric
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Let us know the results. Good or bad!
     
  6. eclayton

    eclayton Sgt. Shorts-cough

    Okay,here are my results, weeks later! I've been busy.

    I ran everything, I"m clean, except for the Altnet spyware which we can't remove.

    Here's my hijack this log.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's not a good idea to run HijackThis from a ZIP file. Your should extract it to a safe directory as recommended in the guides. Otherwise you will not get any backups when using it to fix things.
    However, this did not impact your scan results. You are basically clean, but I wonder why you added the two lines to your hosts file.

    As far as the HKEY_LOCAL_MACHINE:software\altnet\ registry key, how did you find it to begin with (did a scanner detect it, was it Ad-Aware SE)? Have you tried to manual edit the registry (if you are comfortable with doing that)? It would be a good idea to backup the registry first using a program like Erunt
     
  8. eclayton

    eclayton Sgt. Shorts-cough

    I thought I did extract it to it's own folder, but anyway....
    As for the host file, I had tried adding my own entries to the hosts, but I never got any further.

    Ad-Aware SE found this. I have deleted it, both in normal and safe mode, and it doesn't really delete it, it's still there after I "delete" it.

    We went to the Registry and tried deleting it that way, and it won't let us.

    Hope this helps. :(
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like something could be running that protects it. I did not see anything. You are not using HJT's filter capability (to hide known items) are you? Are you logged in with Admin priviledges?

    Is this the full registry key: HKEY_LOCAL_MACHINE:software\altnet

    Any other hits?
    Did you try deleting from the registry in safe mode?

    Did you give that Giant Antispyware a try? It has a 15 day trial.
     
  10. eclayton

    eclayton Sgt. Shorts-cough

    D'oh! I tried to go to it, and it said it was down, and I forgot to go back and try it again. I'll try right now. :rolleyes:

    edit: Nope, still down. :(
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I noticed that too a bunch lately. I wonder what's up with them. I'm not sure if this is the trial version or not but give the one on MG's a try: GIANT AntiSpyware

    How about my other questions?
     
  12. eclayton

    eclayton Sgt. Shorts-cough

    Man, sorry, it was 2 am.....

    Yes, tried to delete the registry entry in both normal and safe mode, I guess I'm logged in with Admin priviledges, I'm logged in as Eric, but I have full priviledges. I didn't enable any filter capability in HJT, but I'll make sure I'm running it correctly.

    When I ran Spybot, I got the following error:

    Error during check!: Z-Demon (Ungültiger Datentyp für '') ()

    It has that and the DSO exploits, but it stops the check. I may try uninstalling and reinstalling it, and running it.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well I figured out what's up with Giant! See this: http://www.microsoft.com/presspass/press/2004/dec04/12-16GIANTPR.asp

    Make sure you have the current version of Spybot & detections updates. It also sounds like you need this patch for it: Spybot - Search and Destroy DSO Exploit Fix

    Is this the only registry key found: HKEY_LOCAL_MACHINE:software\altnet
    What program is finding it? Or are you having a problem that revealed it.

    Was the HJT log you post from safe mode or normal boot? It appears to have so little in it. Not even a virus scan application is showing in the process list (it does show in services but there should be something in the process list unless you shut them down). So I would expect it was from safe mode. If so, post a log from normal boot mode.

    By the way, I would remove those items you added to your hosts file and just leave the default line (127.0.0.1 localhost). Adding lines to hosts does little to protect you from the more advanced malware. Even if you write protect the file, they will just change the attributes and delete it and add there own entries anyway. Also if you start adding items to the hosts file, it starts making it harder to find when bad stuff gets inserted because you have to read thru every line. And sometimes malware will even add lines for good sites but they will not put valid IP address. They will just have the URL linked to their own malware site address or a dead end. This can also get harder to find because now you have to remeber the IP address for all your good sites or you have to check each one by hand. The same logic applies to adding items to your IE Trusted Zone. I never add any. Use Spybot's Immunize feature to add over 1000 items to your restricted zone. That is a good thing to do. Also use SpywareBlaster's protections.
     
    Last edited: Dec 16, 2004
  14. eclayton

    eclayton Sgt. Shorts-cough

    Hey Chaslang,
    Thanks alot for all the help and time you're giving me. I just noticed your title, guess I'm talking to the right person! :D

    Okay, I ran HJT in normal mode, as the instructions said, but I can run it again just to see what else comes up.

    Ad-Aware SE was what found the altnet spyware file, and it only found one registry entry. With repeated scans and deletes, the file just keeps showing up.

    I downloaded the DSO exploit fix, and voila, Spybot was able to complete the scan without the weird "Error during check!: Z-Demon (Ungültiger Datentyp für '' message, and it found 115 problems. However, none of them were the altnet problem. I will run ad-aware again to see what it now finds.

    I've been using Spybots Immunization, but it had been awhile since I last updated the immunization, so 169 additional products are now blocked. I also run SpywareBlaster and update it regularlly.

    I'll run another HJT in normal, just to be sure and get back to you. I also may need a walk through to delete those entries from the hosts file, it's been awhile since I was there, and I'm afraid I won't remember how to do it.

    And thanks again, I really appreciate the time you've taken for me.

    Eric
     
  15. eclayton

    eclayton Sgt. Shorts-cough

    Okay, AltnetBDE is still alive and well. :( Now I'll run HJT.
     
  16. eclayton

    eclayton Sgt. Shorts-cough

    Okay, here tis. I'm wondering about removing

    • both 01s (the host file entries)
    • 02, the Acroreader helper, (I don't think it's necessary but I'm not sure)
    • 016 Symantec Antivirus scanner (I run avast, not symantec)
    • 016 Symantec Utility class
    • 016 Housecall control
    I think the symantec and housecall are left over from the online scans I did

    What are your thoughts? And why doesn't this lousy altnet thing show up?
     

    Attached Files:

  17. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Hey, If your having problems removing Alnet & BDE I would recommend using KazaaBegone 1.25 and BDE Remove. I have used these tools on several machines and never ran into a problem. This program removes all spyware that comes along with KaZaa including Alnet & BDE as well as others, so Its worth a try.
     
  18. eclayton

    eclayton Sgt. Shorts-cough

    I used KazaaBegone, but I will give BDE remove a try. Thanks for the heads up.

    Eric

    edit: I ran it, and it didn't find anything. :confused:
     
  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Ok, Was you using KazaaBegone 1.10 because that version has a bug in it that can break you internet, just making sure you was using the updated new version KazaaBegone 1.25

    edit: There is a control panel icon for BDE, To remove this go into the C:\WINDOWS\system32 directory and remove the file "bdeadmin.cpl"
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Notice how HJT had more items in the process list this time. That was what I was questioning before.
    The AcrobatIEHelper is okay but it up to yo if you need it or not. It is an Adobe Acrobat Internet Explorer application for displaying .pdf files. Either way it is not a problem. And yes the O16 lines are left over from the online scans. You can leave them or remove them. If you do remove them, they will have to be redownloaded anytime you attempt to do the online scans again. I usually let them be to save time later.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O1 - Hosts: 66.98.158.200 forums.majorgeeks.com
    O1 - Hosts: 66.77.183.35 seattle.mariners.mlb.com


    That should take care of your hosts files entries for you.

    Your hosts file is c:\windows\system32\drivers\etc\hosts
    Normally you can just edit it using notepad but that should not be necessary. A rescan with HJT should now show that they are gone.

    Looks like you still have Alnet problems. I think I'll make small registry merge file for you to try. Did you get Erunt. I mentioned it back aways. Use it to backup your registry before we edit it.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay hopefully you have done a registry backup. That is always a good idea no matter how simple the editing may be. Also one more comment (I know you replied to this once), but your sure there is only one entry for Alnet. The reason I ask is because many times the below is in the registry

    Okay if you still have the Alnet problem, paste the below text in the quote box into notepad and save it to a file called altnetfix.reg (make sure it ends in .reg not .txt)

    Then run Windows Explorer (click Start and Select Explore) and locate the altnetfix.ref file and double click on it to merge it into the registy. Click OK or yes to the prompt that you will get about the merge.

    Let me know if this works.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You know one other thing occurred to me. (I'm still think about permissions). I know I asked if you had admin priviledges but you should try the below from with in regedit

    Right click the registry key that has Altnet and select permissions, then advanced and see if you (meaning whoever you are logged in as) have Permission = Full permission and Apply To = keys and subkeys. If not subkeys, click the owner tab, highlight your name and check the box to replace owner, apply and OK. Now you are back on the Security tab! Highlight your name on the security tab and check the Allow full control box. Apply and click advanced again and you should have another entry for your name with keys and subkeys.

    Now try deleting this stinker again.
     
  23. eclayton

    eclayton Sgt. Shorts-cough

    SUCCESS!! Chaslang, you the man!!

    I went into the permissions like you suggested, but I couldn't get it to delete, even after taking ownership of it. But I saw who the previous owner was, went into that persons account, and deleted the key easy as pie! I ran Ad-Aware and confirmed that the key was gone.

    BTW,
    I didn't understand your question at first, but it did indeed have subkeys Dashboard and one key under Dashboard whose name I can't remember.

    This thing was a headache. Thanks a bunch for all your help.

    Eric

     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Eric! Were there is a will, there is a way!
     
  25. tux2460

    tux2460 Private First Class

    I'm not sure if it is proper protocol to ask the same question under the same thread. But I was having the same problem as Eric, I followed all the steps right up to the end, the permissions was the problem.

    HKEY_LOCAL_MACHINE\SOFTWARE\altnet\dashboard\settings
    This key has no permissions, and no one set to owner, and I can't add anyone as owner... I'm kinda stuck here, I don't go into the registry unless I have no choice. So if anyone could tell me if I'm completely screwed here or if there is something I can do about it please let me know.
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you try what I posted in message number 21?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds